Trail of Bits

AlephBFT

Type

Security review

Client

the Aleph Zero Foundation

Date

2021-06

Domain

Blockchain

Effort

4 wks

Section

Substrate

Trail of Bits's security review of the Aleph Zero Foundation (Jun 2021) identified 9 issues: 1 low, and 8 informational.

Findings · 9

  1. 1 Code documentation does not reference the paper Informational
  2. 2 Use of diferent types to represent rounds Informational
  3. 3 Use of incorrect loop break to handle add_to_store and handle_events failures Informational
  4. 4 Incorrect state rollback upon removal of forker’s units Informational
  5. 5 Lack of error handling in Terminal’s post-insert hooks Informational
  6. 6 Diferent byte representations decode to the same data Informational
  7. 7 Errors in async code leave the program in an inconsistent state Low
  8. 8 Blocking I/O in Network trait implementations will block async runtime threads Informational
  9. 9 Inconsistent handling of closed channel errors Informational

Findings extracted from the published report PDF. See the full report below for details and remediation.

Related